Weekly #cybersecurity digest to your inbox

Subscribe for our weekly digest and get each Friday the most important cyber security news, list of upcoming free webinars and a summary of Cyberday development to your inbox.
Thanks! See you in your inbox on Fridays. :)
Unfortunately something went wrong. You can contact us at team@cyberdayai.

Framework recap, US security & and role management: Cyberday product and news summary 3/2025 🛡️

The March product and news update presents updates to role management and the new Trust Center, a review of the key frameworks for 2025 and US security.

article

28.3.2025

Understanding DORA compliance: Key steps to prepare your organization

Understand DORA compliance and get a clear DORA requirements summary with key compliance areas, practical steps, and essential guidelines to strengthen your organization's digital resilience.

article

18.3.2025

ISMS implementation: comparison of documents, wikis, ISMS tools and GRC

There are a few different approaches to building an ISMS. In this post, we’ll compare these different methods, helping you understand which might be the best fit for your organization’s security management needs.

article

6.3.2025

What is Statement of Applicability (SoA) in ISO 27001?

In this blog, we'll cover the main purpose and benefits of a well-working Statement of Applicability document. We'll also explain why SoA is important, and 4 key roles it can play in information security work.

article

4.3.2025

Why is ISO 27001 compliance now more important than ever?

Year after year, ISO 27001 standard has remained one of the gold standards for information security. The global standard has remained relevant, but where did ISO 27001 originate? And why is it's popularity just going up?

article

27.2.2025

10 most common non-conformities in ISO 27001 audits

Audits and non-conformities drive organizations toward continuous improvement. But before your first ISO 27001 certification, it's good to be aware of some most common non-conformities, so you can avoid these in your certification audit.

article

18.2.2025

Got an ISO 27001 audit interview request - what should I expect?

In this blog, we will talk about the importance of employee participation in the audit interview process, why auditors value employee insights, and look into possible questions asked in an ISO 27001 interview.

article

13.2.2025

ISO 27001 compliance and certification checklist

Looking to ensure you fill ISO 27001 requirements? This checklist will present clearly ordered key steps that guide your organization in building an ISMS and getting compliant with the ISO 27001 standard.

article

6.2.2025

Only 8% of businesses that paid a ransom got all of their data back

#Ransomware is brutal. Survey findings from Sophos: 📈 avg cost of recovery +143% (0.76M$ (2020) -> 1.85M$ (2021)) 💰 avg ransom paid 170k$ 🦹 8% of got all their data back after paying a ransom #cybersecurity

Go to article at
29.4.2021

Cybercriminals Widely Abusing Excel 4.0 Macro to Distribute Malware

Cyber criminals taking advantage of an age-old feature. Excel 4.0 macros (XLM) were published in v4.0 back in 1992. These are hard to detect for security solutions. Use is e.g. download and execute ZLoader or Quakbot malware. #cybersecurity

Go to article at
29.4.2021

Five steps to get employees invested in security awareness training

Staff engagement in #cybersecurity training: ✅ Examples - What can happen, if an employee doesn't follow guidelines ✅ Focus on the biggest risks for your organisation or each unit ✅ Clarity - Keep materials short and unambiguous

Go to article at
23.4.2021

Mount Locker Ransomware Aggressively Changes Up Tactics

"Product dev" at #ransomware gangs: ⚠️ double-extortion - from data stealing to leaking ⚠️ apps (e.g. AdFind) for AD user query ⚠️ pen-testing tools for lateral movement on networks ⚠️ scripts to disable detection tools #cybersecurity

Go to article at
23.4.2021

WhatsApp Pink is malware spreading through group chats

☠️ Unusual baiting technique: WhatsApp users sent links masked as an official update, that claim turning the app's theme to pink. If installed, the malicious WhatsApp pink app takes full control of the targeted device. #cybersecurity

Go to article at
21.4.2021

COVID-19-themed cyberattack detections continue to surge

Observations from McAfee report (Q4/2020): 📈 114% increase in COVID-19-themed attacks 📈 69% increase in #ransomware attacks 📈 100% increase in cyber incidents targeting the technology sector #cybersecurity

Go to article at
21.4.2021

Fake Microsoft Store, Spotify Sites Being Used to Spread Infostealing Malware

Malicious advertising campaign ongoing. When ad is clicked, user is taken to fake MS Store / Spotify page that auto-downloads advertised app. .zip will actually contain #malware to steal card info and passwords from browsers. #cybersecurity

Go to article at
21.4.2021

Most users don’t know the capabilities and risks of QR codes

As QR codes rise in popularity, they'll get more leveraged in cyber crime. Some challenges: ⚠️ 37% knew QR code can download an app ⚠️ 22% knew QR code can share location ⚠️ Identifying a malicious QR code harder than URL #cybersecurity

Go to article at
21.4.2021

FBI nuked web shells from hacked Exchange Servers without telling owners

As guidance and do-it-yourself tools had already been utilized, FBI got a search warrant and went in to clean still-compromised MS Exchange servers themselves - ending up successfully uninstalling hundreds of web shells. #cybersecurity

Go to article at
14.4.2021